Skip to content
Exploitative Patternsin Games

When does a pattern become harmful?

For the purposes of this research exploration, we understand deception not the same way as harm. Our catalogue describes what a technique does but this rubric lets you judge how harmful a given instance may be.

First: whose purpose does it serve?

Before weighing how harmful a mechanic is, we have to ask why it exists. We tagged every pattern here based on the purpose it serves, so consider this a fast first test for separating a standard from a deceptive game mechanic.

Serves gameplay

Serves primarily for the player's experience, which is usually a standard mechanic that players willingly accept.

Gameplay & business

Serves play and the business/creator at once, which is a contested middle space where the conditions below decide the harm.

Serves business

Serves primarily for revenue, retention, or data. These patterns are most exploitative and clearest dark-pattern candidates.

Scoring Severity & Evidence

Beyond their purpose, we assign every pattern two independent scores.Severity is how serious the harm can be when the pattern is included in a game. Evidence rates how strong the research base is that it actually causes harm. They are orthogonal dimensions: a pattern can be severe but barely studied, or well-evidenced yet modest in impact.

Severity — how serious

  • LowTrivial or easily reversed stakes — a mild, resistible nudge.
  • MediumReal but bounded detriment; depends heavily on context and dose.
  • HighClear, substantial loss of money, time, or autonomy.
  • SevereLarge or escalating loss, or harm aimed at the vulnerable — a prohibition candidate.

Evidence — how sure

  • EmergingEarly or indirect: theory, a single study, an expert report, or analogy from another domain.
  • ModerateSeveral studies or consistent correlational findings; recognised in the literature.
  • StrongReplicated, meta-analytic, or convergent evidence — e.g. loot boxes and problem gambling.

Four tests: how a pattern fails the player

Severity and evidence say how bad and how sure. This last lens says how a pattern fails its player — through four questions about the communication a game owes the people playing it. The top two are informational pressures (what the player is told); the bottom two arepsychological pressures (what the player is allowed to choose).

HonestyIs it deceptive to the player?

The mechanic communicates something false — a fake discount, a manufactured “almost”, a misleading label.

TransparencyIs the mechanic hidden from the player?

Key facts are withheld rather than misstated — undisclosed odds, obscured real-money cost, buried terms.

ControlAre players forced to opt in?

Engagement is imposed by default or by interruption — preselected purchases, forced registration, unskippable prompts.

ConsentCan players not opt out before they engage?

There is no real exit once it starts — obstructed cancellation, sludge, penalties for leaving.

The map below plots every pattern by the test(s) it fails — a single failure sits in that quadrant, two failures move to the shared edge between them, and a pattern that fails all four pulls to the centre. Dots are coloured by severity. The patterns beneath the grid failnone of the four tests yet remain harmful — the transparent-but-exploitative cases that honesty, transparency, control, and consent rules cannot reach.

Each dot is one pattern, placed by the communication test(s) it fails and coloured by severity. Hover to name it, click to open — or browse all patterns.

Acceptable
Concerning
Harmful
Impermissible

increasing severity →

Eight conditions

Each dimension pushes a given instance greener (more acceptable) or darker (more harmful). When locus + consent + vulnerability all tip darker, the case for “harmful” — and at the extreme “impermissible” — is strongest.

DimensionGreenerDarker
Asymmetry of benefitMutual, or player-favouring.Strongly provider-favouring at the player's expense.
Consent & expectationThe player opted into this kind of influence; the mechanism is overt.Covert; outside what was consented; 'consent' was manufactured by another pattern.
Locus (diegetic vs commercial)Deception lives inside the consented fiction / fair-play (a bluff, a twist).Deception or extraction operates on the player-as-consumer (store, billing, data).
Materiality of harmTrivial stakes.Large or escalating loss of money, time, or data.
Pressure intensityGentle, resistible nudge.Aggressive, repeated, scarcity/urgency-laden coercion.
Reversibility & exitEasy to undo, refund, cancel, or disable.Locked-in; obstructed exit; non-refundable.
Transparency of material infoCosts, odds, and terms are clear and timely.Odds or costs are hidden, delayed, or obfuscated.
Vulnerability of targetCompetent, informed adult.Children, problem gamblers, 'whales', cognitively loaded or impaired users; SES-correlated targeting.

Severity gradient

Tier 1
Strongest evidence · candidates for prohibition

Randomised paid mechanics (loot boxes/gacha), especially with hidden odds and especially to minors; manipulative monetisation targeting children.

Tier 2
Clear consumer detriment · growing evidence

Obstructed exit / sludge, hidden costs, premium-currency obfuscation, aggressive FOMO, and pay-to-win in competitive contexts.

Tier 3
Context-dependent · harmful mainly under the rubric

Grinding, daily streaks, timers, and social/parasocial nudges — ordinary engagement design that turns harmful chiefly when combined with monetisation, covert operation, or vulnerable targets.

Bright-line “do-not-ship” list

The highest-confidence prohibitions, where the evidence and the rubric converge — specific enough for a regulator to enforce and a studio to test against.

  1. 1Paid randomised rewards (loot boxes/gacha) offered to children, or in games rated for minors.
  2. 2Undisclosed probabilities on any paid randomised reward.
  3. 3Real-money cost obfuscation (multi-step currency laundering) targeting minors.
  4. 4Obstructed cancellation / refund and withdrawal “sludge” on recurring or large spends.
  5. 5Ads disguised as gameplay, and purchase-as-default UI in children's titles.
  6. 6Designs that individually profile and price to maximise a specific player's spend.

Five modes of adversarial design

A family of near-synonyms, separated by what exactly is wrong. They stack: one feature can be several at once.

Coercive

Intent: No (effect-based)

Removes, withholds, or penalises acceptable alternatives; applies pressure.

Operates on the choice set / freedom · e.g. Forced action; obstructed exit; withholding progression to compel pay; play-by-appointment.

Deceptive

Intent: No

Induces or exploits a false belief about a material fact.

Operates on beliefs (epistemic) · e.g. Hidden odds; disguised ads; value obfuscation.

Exploitative

Intent: No (effect-based)

Takes unfair advantage of an asymmetry or vulnerability for the provider's gain — even if the user is not deceived.

Operates on fairness / autonomy / vulnerability · e.g. Loot boxes; whale-targeting; SES-targeted monetisation.

Malicious

Intent: Yes (intent-laden)

Design deliberately built or deployed to work against the user's interest.

Operates on intent + effect · e.g. Patented spend-maximisation; covert data capture; 'malicious interface design'.

Manipulative

Intent: Usually covert

Bypasses or subverts rational agency via bias, emotion, or hidden influence.

Operates on the decision process · e.g. Near-miss; variable-ratio rewards; confirmshaming.